Intellectual Property and Copyright
AI-generated does not mean we own it, and sometimes it means nobody can. Rights in AI-assisted work depend on what went in, the terms of the tool, the law of each market and what people actually contributed. Leaders who keep those questions separate, and keep a record for the assets that matter, can move fast without building on sand.
After this chapter you can
- Distinguish copyright, patents, trademarks and trade secrets as different AI risks.
- Explain why input rights and output rights are separate questions at every stage.
- Describe the US position on purely AI-generated material and why the UK and other markets may differ.
- Recognize unapproved AI tools as a trade-secret leakage channel and indemnities as conditional.
- Scale review and provenance records to the value and exposure of the asset.
In September 2022 the US Copyright Office registered a comic book called Zarya of the Dawn. Its author, Kristina Kashtanova, had written the story and laid out the pages; the pictures came from an AI image generator. She held a certificate of registration. Five months later the Office cancelled it and issued a narrower one. The text was hers. So was the selection and arrangement of words and pictures on the page. The images themselves, the Office said, were not the product of human authorship and were protected by no one1.
That is the contradiction at the center of this chapter. A comic can be protected while every picture in it is not. A company can hold an asset, use it, sell it and still be unable to stop a competitor from copying it. Many executives assume that whoever makes or pays for a piece of work owns it. With AI, that assumption fails in specific and predictable ways.
The contract says yours; the law may say nobody’s
Read the terms of many major AI services and you will find reassuring language about outputs. One widely used provider’s terms say the customer owns the output and that the provider assigns to the customer all of its rights in the output, “if any”2. Those two words carry the weight. A provider can only hand over what exists. If the law grants no copyright in a purely generated image, the assignment transfers very little.
So the core idea is simple to state. AI-generated does not automatically mean we own it, and in some cases it means nobody can. Nor does it mean original, unrestricted or safe to commercialize. Each of those is a separate question, and each needs an answer before an AI-assisted asset leaves the building. AI changes the speed and scale of creation; it does not make intellectual-property questions go away. It multiplies them, because there is far more content, made far faster, with far less visibility into where it came from. The US government’s risk profile for generative AI lists intellectual property among its twelve core risks for exactly that reason3.
Four rights, four different risks
Intellectual property is not one right but a family, and AI touches each member differently. When someone in a meeting says “the IP question”, the first useful response is to ask which one.
Copyright protects original expression: text, images, music, video and software code. AI meets copyright three times, as the material it learned from, as the material you feed it and as the material it produces. Patents protect inventions, and AI raises the question of who invented something. In December 2023 the UK Supreme Court held that an AI system cannot be named as an inventor on a patent application; an inventor must be a person4. Where AI contributes to research, the evidence of what your people conceived matters. Trademarks protect names, logos and slogans. A generated campaign image can drift close to a competitor’s mark, or reproduce one outright. Trade secrets protect valuable information that is not generally known, but only while the owner takes reasonable measures to keep it secret. Source code, pricing models, customer lists and process know-how all qualify, and all of them can be pasted into a chat window in seconds.
Risk enters at four stages, not at publication
Many organizations think about IP only at the moment of release, when legal reviews the campaign or the product. By then, much of the risk is already inside the asset. It is more useful to follow an asset through its life.
At input, someone gives the system an article, a photograph, a competitor’s brochure or a block of code. Publicly available does not mean free for any use. At the tool, the provider’s terms decide what happens to that input, what the provider may do with it and what the customer receives; terms differ by product, plan and region, so the only terms that matter are those of the service your people actually used. At output, the question is whether the result reproduces or closely resembles existing work. New to us is not the same as legally unrestricted. At release, the asset goes into a product, a campaign or a customer deliverable, and a mistake becomes expensive.
The most prominent legal fights so far concern a fifth stage that sits with the providers: training. A US court gave final approval in July 2026 to a 1.5 billion dollar settlement over books used to train a model5, and in November 2025 the UK High Court largely ruled for a model maker against a photo agency6. For a company that buys AI rather than builds it, those cases matter mainly through vendor due diligence. Your direct exposure is what your people put in and what they ship.
What the law protects, and what it does not
The ownership question needs care, and it varies by country. In January 2025 the US Copyright Office published its report on the copyrightability of AI output. Its conclusion is that material generated purely by AI is not copyrightable. Prompts alone, however detailed, do not give a person enough control over the output to make them its author. What can be protected is the human part: creative work that is visible in the output, the creative selection and arrangement of generated material, and creative modifications made to it7. The courts agree. In Thaler v. Perlmutter, a federal appeals court upheld the refusal to register an image whose only listed author was an AI system, and on 2 March 2026 the Supreme Court declined to hear the case8.
Other countries differ. Since 1988 UK law has contained a provision, section 9(3) of the Copyright, Designs and Patents Act, under which the author of a computer-generated work is the person who made “the arrangements necessary” for it. How far that provision reaches modern generative AI has not been settled by the courts. In March 2026 the UK government said it would keep that provision under review and proposed to remove it unless evidence shows ongoing value, while keeping protection for works made with AI assistance9. So the US answer does not travel automatically, and the UK answer may change. What travels everywhere is documented human contribution.
The practical consequence is commercial, not academic. If a logo, a product design or a block of code is purely generated, a competitor may be free to copy it, and you may have little to enforce. That is a weak foundation for a brand asset or a differentiating product. It is a fine foundation for an internal draft.
Trade secrets leak on the way in
The second IP risk has nothing to do with who owns the output. It is about what leaves on the way in. A developer on deadline pastes proprietary code into a free chatbot to ask why it fails, or an analyst pastes a pricing model to tidy it up. Nobody intends a leak; each person is asking for help with their work. A widely reported case, at Samsung in 2023, is told in What Is AI Governance? in Module 0710.
Privacy and Confidential Data treated this pattern as a data-protection problem. For intellectual property it is sharper, because a trade secret exists only while its owner takes reasonable measures to keep it secret. Letting valuable code or formulas flow into tools the company does not control is precisely the kind of fact an opponent will use to argue that those measures were not reasonable.
Many organizations’ first move is a ban, and a ban is understandable as an emergency brake. As a standing policy it tends to push use into personal accounts, which is the top-left corner of the grid. The more durable answer is approved enterprise tools whose terms you have read, clear rules on which classes of information may go in, and controls that tighten as the value of the information rises.
Terms, indemnities and generated code
Two contractual instruments shape your position, and both reward reading the small print. The first is the provider’s terms on inputs and outputs, discussed above. The second is the indemnity, a promise by the provider to defend you if someone sues over the output. These are valuable, and they come with conditions. One large provider’s copyright commitment, for example, covers paying commercial customers only if they used the guardrails and content filters built into the product, and does not extend to free or consumer versions11. An indemnity can pay a settlement. It cannot restore a leaked trade secret, and it does not make an output yours.
Software is where the abstract becomes concrete, because generated code can carry someone else’s license with it. Open source is not free of obligations; some licenses require attribution, and some require that a product built on the code release its own source. Black Duck, which audits codebases during acquisitions, found open source in 98 percent of the 947 codebases it examined for its 2026 report and license conflicts in 68 percent, up from 56 percent a year earlier. It points to AI coding assistants as a driver. Those figures count audited codebases. A separate Black Duck survey counts organizations: 76 percent check AI-generated code for security risks, but only 54 percent check it for IP and license risks12.
Review depth follows the stakes
None of this argues for a lawyer behind every prompt. Much AI-assisted work is internal, low-value and short-lived. The right control is proportionate: review deepens as the asset’s value and exposure rise.
At the top tier sits the provenance record: which tool and version produced the material, what went in and where it came from, what your people selected, arranged and changed, what review happened and who decided to release it. The record is short. Its value shows up later, when a customer, an acquirer or a court asks where an asset came from. An AI-assisted asset without one is like a painting bought with no provenance: it hangs on the wall and may be valuable, but you cannot prove the seller had the right to sell it, or stop others from copying it. Zarya of the Dawn kept its narrower registration precisely because its author could show what she wrote and how she arranged the pages. How such records become a governance process is the subject of Module 07.
Story: the marketing image nobody could vouch for
For Wizards of the Coast, art is much of the product: the illustrations on its cards and in its books are what players collect. In August 2023 players spotted signs of AI in illustrations for a forthcoming Dungeons & Dragons sourcebook. The company said it had not known that an artist had used AI, and that it was “revising our process and updating our artist guidelines to make clear that artists must refrain from using AI art generation as part of their art creation process”13. It later replaced the affected art14. In December 2023 it set the same line for Magic: “We require artists, writers, and creatives contributing to the Magic TCG to refrain from using AI generative tools to create final Magic products”14.
On 4 January 2024 the company posted a promotional image for Magic on social media15. Players pointed to signs of generation, such as wires that led nowhere and bulbs with impossible filaments. The company replied, in a post it later deleted, “This art was created by humans and not AI.” On 7 January it reversed itself: “Well, we made a mistake earlier when we said that a marketing image we posted was not created using AI.” AI components now appearing in industry-standard tools such as Photoshop, it explained, had “crept into our marketing creative, even if a human did the work to create the overall image”16. Its explanation pointed to a third-party vendor that had supplied the work15.
The company had a rule; what it lacked was a way to check it. The rule bound the artists who made products, not the vendors who made marketing. Nothing on file recorded which tools had produced the image, so the first public answer had to come from belief rather than evidence, and it did not survive three days. And the tools themselves had moved: once generative features sit inside mainstream editing software, “did we buy an AI tool?” no longer answers “is there AI in this asset?”. For a business built on art it owns, there is a rights question underneath as well, since in the US purely generated elements are not protectable7.
The fix the company announced was a process, not a single takedown. It said it needed “to update the way we work with vendors on creative beyond our products—like marketing images we use on social media,” and it called for more transparency and better disclosure as generative AI becomes standard in tools such as Photoshop17. That is the provenance record of this chapter, written into supplier relationships. The lesson is not about one publisher: any organization that buys creative work, code or content now needs suppliers to say what made it.
What this means for leaders
Four habits follow. Separate the questions: whether we may use the input, what the terms say, whether the output is clean and whether we can own it are four answers, not one. Protect what goes in, because a trade secret lost to an uncontrolled tool cannot be recalled and no indemnity restores it. Make the human contribution visible for anything you intend to protect, since that is what US law protects. And scale review to the stakes, so that drafts move fast and commercial assets carry a record.
Check yourself
- If our AI tool created it and the provider’s terms assign the output to us, the company owns the copyright.
- In the US, a detailed enough prompt makes the person who wrote it the author of the output.
- A work can be registered for copyright even though some images in it are AI-generated.
- A provider indemnity means we carry no IP risk.
- Pasting proprietary code into an unapproved AI tool can weaken trade-secret protection.
- Generated code is original, so it cannot carry open-source license obligations.
Reflection: trace one asset
What comes next
Every answer in this chapter rests on a provider: the organization whose model, terms and indemnities you depend on. The next chapter, Model and Third-Party Risk, asks what happens when that provider is itself the risk.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
US copyright and AI-generated work · US
US Copyright Office, Copyright and Artificial Intelligence Part 2: Copyrightability (Jan 2025); Thaler v. Perlmutter (D.C. Cir. 2025; cert. denied 2 Mar 2026)
Material generated purely by AI is not copyrightable; human-authored contributions (selection, arrangement, modification) can be. Nobody may own a purely AI-generated asset, so competitors may be free to copy it. Other countries differ (e.g. the UK's computer-generated works provision).
Last verified 2026-10-06
References
- U.S. Copyright Office. Letter re: Zarya of the Dawn (Registration # VAu001480196). U.S. Copyright Office. 2023.
- OpenAI. Terms of Use. OpenAI. 2024.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1. NIST. 2024.
- The Supreme Court of the United Kingdom. Thaler v Comptroller-General of Patents, Designs and Trade Marks [2023] UKSC 49. The Supreme Court of the United Kingdom. 2023.
- The Authors Guild. Court Grants Final Approval of 1.5 Billion Dollar Anthropic Copyright Settlement. The Authors Guild. 2026.
- Cleary Gottlieb. UK High Court Issues Landmark Ruling in Getty Images v. Stability AI, with Narrow Trademark Infringement Win for Getty; Claim of Secondary Copyright Infringement Fails. Cleary Gottlieb Steen & Hamilton. 2025.
- U.S. Copyright Office. Copyright and Artificial Intelligence, Part 2: Copyrightability. U.S. Copyright Office. 2025.
- Finnegan. Supreme Court Declines to Hear Thaler v. Perlmutter, Leaving Human Authorship Requirement Intact. Finnegan, Henderson, Farabow, Garrett & Dunner. 2026.
- UK Government (Department for Science, Innovation and Technology; Intellectual Property Office). Report on Copyright and Artificial Intelligence. GOV.UK. 2026.
- Mark Gurman. Samsung Bans Staff's AI Use After Spotting ChatGPT Data Leak. Bloomberg. 2023.
- Microsoft. Microsoft announces new Copilot Copyright Commitment for customers. Microsoft On the Issues. 2023.
- Black Duck. Black Duck Research Shows Open Source Vulnerabilities Have Doubled as AI Accelerates Code Creation (2026 OSSRA report). Black Duck. 2026.
- Matt Bassil. Wizards promises new guidelines to keep AI art out of DnD. Wargamer. 2023.
- James Whitbrook. Magic: The Gathering Formally Bans the Use of Generative AI in 'Final' Products. Gizmodo. 2023.
- Tara McCauley. Magic: The Gathering Admits AI Used in Marketing Image. The Escapist. 2024.
- Futurism. Wizards of the Coast Denies "Magic: The Gathering" Art Was AI-Generated, Then Admits It Was. Futurism. 2024.
- Wizards of the Coast. An Update on Generative AI Tools and Magic. Wizards of the Coast (magic.wizards.com). 2024.
Further reading
- U.S. Copyright Office. Copyright and Artificial Intelligence, Part 2: Copyrightability. U.S. Copyright Office. 2025.
- UK Government (Department for Science, Innovation and Technology; Intellectual Property Office). Report on Copyright and Artificial Intelligence. GOV.UK. 2026.
- Black Duck. Black Duck Research Shows Open Source Vulnerabilities Have Doubled as AI Accelerates Code Creation (2026 OSSRA report). Black Duck. 2026.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1. NIST. 2024.
Sources last verified 2026-10-08.